Splunk Search

Can we Ignore timechart column if all rows having 0 values ?

AKG1_old1
Builder

Hi,

How can we Ignore timechart column if all rows having 0 values.

basically I am using trellis to display and want to ignore charts which doen't have any data.

alt text

alt text

0 Karma
1 Solution

somesoni2
Revered Legend

Try this

your current search before the timechart command
| where Issues_Count>=0
| timechart span=1h cont=false values(Issues_Count) as Issues_Count by Alert_Description limit=20

View solution in original post

0 Karma

somesoni2
Revered Legend

Try this

your current search before the timechart command
| where Issues_Count>=0
| timechart span=1h cont=false values(Issues_Count) as Issues_Count by Alert_Description limit=20
0 Karma

AKG1_old1
Builder

thank you 🙂 some times simple answer won't click in mind and keep looking for complex solution.

0 Karma

mayurr98
Super Champion

try this :

| bucket span=1h _time
 | chart values(Issues_Count) as Issues_Count by _time Alert_Description limit=20

also, try :

| timechart span=1h cont=false values(Issues_Count) as Issues_Count by Alert_Description limit=20
0 Karma

AKG1_old1
Builder

@mayurr98 : thanks for response. but not working 😞

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...